Etuldan / spaRSS

Based on Flym and Sparse RSS, this checks RSS/Atom news feeds, polling for updates from the device on a regular basis. Fetched items are available for offline reading.
Other
146 stars 31 forks source link

insecure gradlew #287

Open IzzySoft opened 5 years ago

IzzySoft commented 5 years ago

Could you please "secure your gradlew"?

Found plain HTTP URL for gradle repository:
build/net.etuldan.sparss.floss/mobile/build.gradle
repositories {
    maven {
        url 'http://dl.bintray.com/amulyakhare/maven'
    }
gradle build uses plain HTTP URLs for repositories!  This is insecure!
https://max.computer/blog/how-to-take-over-the-computer-of-any-java-or-clojure-or-scala-developer/

AFAIK Bintray does support HTTPS :wink:

(above copy-paste is from F-Droid's lint process)